HP VPN Firewall Appliances Network Management Configuration Guide

850
Figure 405 Network diagram
Configuration procedure
1. Configure Firewall:
# Configure RIPng.
<Firewall> system-view
[Firewall] ipv6
[Firewall] ripng 1
[Firewall-ripng-1] quit
[Firewall] interface gigabitethernet 0/1
[Firewall-GigabitEthernet0/1] ipv6 address 150::1 64
[Firewall-GigabitEthernet0/1] ripng 1 enable
[Firewall-GigabitEthernet0/1] quit
[Firewall] interface gigabitethernet 0/2
[Firewall-GigabitEthernet0/2] ipv6 address 151::1 64
[Firewall-GigabitEthernet0/2] ripng 1 enable
[Firewall-GigabitEthernet0/2] quit
# Configure Node 10 for policy lab1 to forward IPv6 packets with a length of 64 to 100 to the
next hop 150::2/64, and IPv6 packets with a length of 101 to 1000 bytes to the next hop
151::2/64.
[Firewall] ipv6 policy-based-route lab1 permit node 10
[Firewall-pbr6-lab1-10] if-match packet-length 64 100
[Firewall-pbr6-lab1-10] apply ipv6-address next-hop 150::2
[Firewall-pbr6-lab1-10] quit
[Firewall] ipv6 policy-based-route lab1 permit node 20
[Firewall-pbr6-lab1-20] if-match packet-length 101 1000
[Firewall-pbr6-lab1-20] apply ipv6-address next-hop 151::2
[Firewall-pbr6-lab1-20] quit
# Configure IPv6 interface PBR by applying policy lab1 to GigabitEthernet 0/3.
[Firewall] interface gigabitethernet0/3
[Firewall-GigabitEthernet0/3] ipv6 address 192::1 64
[Firewall-GigabitEthernet0/3] undo ipv6 nd ra halt
[Firewall-GigabitEthernet0/3] ripng 1 enable
[Firewall-GigabitEthernet0/3] ipv6 policy-based-route lab1
[Firewall-GigabitEthernet0/3] return
2. Configure RIPng for Router A.
<RouterA> system-view
[RouterA] ipv6